Files
vmall/openspec/changes/archive/2026-09-17-foundation-auth/specs/rbac/spec.md
T

815 B

Spec delta: rbac

ADDED Requirements

Requirement: Role model

The system SHALL support roles platform_admin, shop_owner, shop_staff, customer. Shop roles MUST carry a shop_id scope.

Scenario: seeded platform admin

  • WHEN migrations run on a fresh database
  • THEN a platform_admin account exists and can log in

Requirement: Role enforcement

Protected routes SHALL declare required roles; the API MUST reject requests with insufficient role using 403.

Scenario: customer hits admin route

  • WHEN a customer token calls an /api/admin/* route
  • THEN the API returns 403 with code FORBIDDEN

Scenario: shop scope isolation

  • WHEN a shop_owner of shop A accesses /api/shop/* resources of shop B
  • THEN the API returns 403 or 404, never the data